Brinks Home Hit via Microsoft Entra Vishing

eSecurity Planet · Medium sophistication
Last updated August 1, 2026

Brinks Home says it is investigating a cybersecurity incident after the ShinyHunters group claimed it broke in by calling employees and tricking them into approving Microsoft Entra authentication actions. The attacker is threatening to publish data it claims to have stolen, including alleged Salesforce customer records and employee information.

How the Attack Reportedly Worked

Brinks Home has said it is investigating a cybersecurity incident after the group ShinyHunters claimed responsibility, stating the intrusion began with a Microsoft Entra vishing campaign. Rather than exploiting a software flaw, the described method relied on phone calls to employees, persuading them to approve authentication requests, register attacker-controlled devices, or complete identity verification steps. If successful, these actions would grant attackers legitimate-looking access to corporate accounts, bypassing many technical controls entirely.

Brinks Home confirmed that the attacker threatened to publicly release data but has not confirmed what, if anything, was actually accessed. ShinyHunters has alleged theft of Salesforce customer records, employee PII, and large volumes of customer support chat logs, but these claims have not been independently verified.

Why This Type of Attack Succeeds

Vishing campaigns targeting identity systems succeed because they exploit the human element rather than a technical vulnerability. Employees are conditioned to be helpful and responsive to IT-sounding requests, especially when a caller frames the situation as urgent, such as stopping suspicious activity or restoring account access. When an employee approves an authentication prompt or allows a new device to be registered, the resulting access looks legitimate to monitoring systems, making detection harder after the fact.

What to Watch For

Defenders and employees should be alert to several warning signs:

  • An unsolicited phone call asking you to approve an authentication or MFA prompt you did not initiate
  • Pressure or urgency to act immediately on an identity-related request
  • Requests to enroll a new device or change authentication settings during a call
  • Callers claiming to be internal IT or Microsoft Entra support without a way to verify their identity

These tactics target all employees, but help desk staff, IAM teams, and customer support are especially attractive targets because of the access and trust associated with their roles.

Building Resistance

Organizations can reduce exposure to this style of attack by:

  • Treating unexpected calls about account security as suspicious and verifying requests through a known internal IT channel before approving any login prompt
  • Training employees to never approve authentication prompts they did not start, and to report them immediately
  • Strengthening help desk identity verification procedures and restricting who can enroll new devices or MFA methods
  • Monitoring Microsoft Entra, Salesforce, and other cloud platforms for unusual authentication activity

Because this technique targets identity rather than infrastructure, technical controls alone are not enough. Combining phishing-resistant MFA, tighter help desk verification, and ongoing monitoring gives organizations a better chance of catching these attempts before access is granted.

Key findings

  • Brinks Home is investigating an incident after attackers claimed they used a Microsoft Entra voice phishing (vishing) campaign against employee identities.
  • Brinks Home confirmed the attacker threatened to release data publicly, but did not confirm what data was accessed.
  • ShinyHunters alleges theft of Salesforce customer records, employee PII, and millions of customer support chat logs (claims not independently verified).
  • The described method focuses on manipulating employees to approve login/authentication activity rather than exploiting a software vulnerability.
  • The article recommends phishing-resistant MFA, stronger identity verification (especially help desk), and monitoring for unusual authentication activity in Entra and SaaS apps.

Who’s being targeted

  • Commonly targeted roles: All employees, IT helpdesk, Identity & access management (IAM) team, Customer support, Security operations (SOC), Finance/Legal leadership (extortion readiness).
  • Affected industries: Residential security services, Smart home / home automation, SaaS / cloud services (Salesforce identity ecosystems).
  • Attack channels: vishing.
  • Impersonated: Internal IT Helpdesk / Microsoft Entra support.

Red flags to watch for

  • Unsolicited phone call asking you to approve an authentication prompt
  • Pressure/urgency to act immediately on an authentication request you did not initiate
  • Requests to enroll/register a new device or change authentication settings during the call
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What happened in the Brinks Home incident?

Brinks Home said it is investigating a cybersecurity incident after ShinyHunters claimed to have breached the company using a Microsoft Entra vishing campaign targeting employees.

How did the attackers reportedly gain access?

According to the claims, attackers called employees and persuaded them to approve authentication requests, register attacker-controlled devices, or complete identity verification steps that granted access to corporate accounts.

What data was allegedly stolen?

ShinyHunters alleges theft of Salesforce customer records, employee PII, and customer support chat logs, though Brinks Home has not confirmed what data was accessed and these claims are not independently verified.

How can organizations defend against this type of attack?

Recommended defenses include strengthening help desk identity verification, restricting unauthorized device registration and MFA enrollment, and monitoring Microsoft Entra and Salesforce for unusual authentication activity.

Read the video transcript

Brinks Home just got hit because employees answered one bad question: “Can you approve that Microsoft Entra prompt for me?” The caller says, “Hi, this is IT support. We’re seeing an authentication issue in Microsoft Entra, can you approve the verification prompt so we can secure your access?” That’s the whole play. According to ShinyHunters, this Microsoft Entra vishing trick let them get into Salesforce, employee data, even millions of support chats, without hacking software, just convincing people to tap Approve. If you ever get a surprise call about your account, and they want you to approve a prompt, your move is simple: hang up, and call your real IT number or open the official ticketing tool to verify first.

Categories

Similar attacks

Vishing Led to Okta Takeover at McKesson

Vishing Led to Okta Takeover at McKesson

McKesson disclosed a breach tied to unauthorized access of third-party applications and data theft affecting some customers. The ShinyHunters extortion group claims it used phone-based social engineering (vishing) to steal employee credentials, took over Okta single sign-on accounts, and then…

August 31, 2026
McKesson Hit via Vishing to Okta Accounts

McKesson Hit via Vishing to Okta Accounts

McKesson confirmed a cyber incident after the ShinyHunters extortion group claimed it stole roughly 284 million patient-related records. The attacker claims the initial access came from phone-based social engineering (vishing) against employees to compromise Okta single sign-on accounts, then pivot…

September 1, 2026
Helix Extortion Hit Uber Freight via Helpdesk Vishing

Helix Extortion Hit Uber Freight via Helpdesk Vishing

Uber Freight is investigating unauthorized access after the Helix extortion group claimed it stole nearly one million files from company cloud and email repositories. Google-linked research says the broader cluster (UNC6671) commonly gets in by calling employees and posing as IT helpdesk staff…

August 12, 2026
BlackFile Crew Vishing Hits PE and Finance Firms

BlackFile Crew Vishing Hits PE and Finance Firms

Google and Reuters report a real vishing-led intrusion campaign tied to the extortion crew behind the retired “BlackFile” brand (tracked as UNC6671). Attackers call employees on personal phones spoofing the corporate IT help desk, push a same-day “passkey/MFA update,” and send them to a look‑alike…

August 12, 2026
Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026
Fake IT Help-Desk Calls Steal M365 Sessions

Fake IT Help-Desk Calls Steal M365 Sessions

Arctic Wolf reports a wave of phone-based social engineering where attackers pose as internal IT, guide executives through “routine” MFA/passkey setup, and then send a company-branded login link that steals Microsoft 365 credentials and session tokens. Once inside, attackers methodically inventory…

September 8, 2026